Bug 216022 - www-client/opera: Release 9.27 fixes various security issues (CVE-2008-{1761,1762,1764})
Bug#: 216022 Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: Linux Status: RESOLVED Severity: normal Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: hanno@gentoo.org
Component: Vulnerabilities
URL:  http://www.opera.com/docs/changelogs/linux/927/
Summary: www-client/opera: Release 9.27 fixes various security issues (CVE-2008-{1761,1762,1764})
Keywords:  
Status Whiteboard: B2 [glsa]
Opened: 2008-04-03 11:00 0000
Description:   Opened: 2008-04-03 11:00 0000
From Changelog:
Security

    * Fixed an issue where newsfeed prompts could cause Opera to execute
arbitrary code, as reported by Michal Zalewski. See our advisory.
    * Solved an issue where resized canvas patterns could cause Opera to
execute arbitrary code, as reported by Michal Zalewski. See our advisory.
    * Improved keyboard handling of password inputs, as reported by Trystan S. 

No CVEs yet.

------- Comment #1 From Robert Buchholz 2008-04-03 13:22:59 0000 -------
*** Bug 216021 has been marked as a duplicate of this bug. ***

------- Comment #2 From Jeroen Roovers 2008-04-03 15:18:05 0000 -------
# ChangeLog for www-client/opera
# Copyright 2002-2008 Gentoo Foundation; Distributed under the GPL v2
# $Header: /var/cvsroot/gentoo-x86/www-client/opera/ChangeLog,v 1.209
2008/04/03 15:14:14 jer Exp $

*opera-9.27 (03 Apr 2008)

  03 Apr 2008; Jeroen Roovers <jer@gentoo.org> +opera-9.27.ebuild:
  Version bump (bug #216022)

------- Comment #3 From Christian Faulhammer 2008-04-03 16:40:35 0000 -------
Thanks Jer. Let's go arches.
Target:
www-client/opera-9.27
KEYWORDS="amd64 ppc sparc x86 ~x86-fbsd"

------- Comment #4 From Markus Meier 2008-04-03 19:47:48 0000 -------
amd64/x86 stable

------- Comment #5 From Tobias Scherbaum 2008-04-06 20:23:46 0000 -------
ppc stable

------- Comment #6 From Jeroen Roovers 2008-04-07 16:48:04 0000 -------
Marked stable for SPARC.

------- Comment #7 From Jeroen Roovers 2008-04-07 16:53:53 0000 -------
opera-9.26.ebuild removed from the tree.

------- Comment #8 From Peter Volkov 2008-04-08 05:41:22 0000 -------
Fixed in release snapshot.

------- Comment #9 From Robert Buchholz 2008-04-14 23:03:28 0000 -------
GLSA 200804-14